CVE-2025-71422: Contrast before 1.12.1 Insecure LUKS2 Persistent Storage

Published Sep 27, 2026
·
Updated

Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not authenticated and, with cryptsetup versions prior to 2.8.1, a header specifying the null keyslot encryption algorithm (ciphernull-ecb) is accepted without error. Because the Contrast Initializer assumes a device is protected if cryptsetup open succeeds with the secret seed, the guest will open the attacker-supplied volume and write secret data in plaintext, or under a volume key known to the attacker, allowing the host to read confidential data that should have been encrypted. Contrast v1.12.1 ships cryptsetup 2.8.1, which disables null ciphers in keyslots when the passphrase is non-empty; v1.13.0 adds detached-header validation in guest memory and integrity protection for secure persistent storage. Contrast persistent volumes were not integrity protected, so integrity impact is not considered.

Affected Software

2 affected components
Edgeless Systems Contrast<1.12.1
cryptsetup cryptsetup<2.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Contrast to a version that resolves this vulnerability.

    Fixed in 1.13.0

Event History

Sep 27, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using Contrast secure persistent volumes in versions before 1.12.1 are exposed when a malicious host can supply a crafted LUKS2 volume to a pod VM. The issue concerns confidentiality of data written to those volumes.

2

What does an attacker need to exploit it?

The attacker needs control of the host sufficient to provide a crafted LUKS2 volume to the pod VM. They can use LUKS2 metadata that specifies the null keyslot encryption algorithm, which older cryptsetup accepts when opening the volume with the secret seed.

3

How can the issue be remediated?

Upgrade to Contrast v1.12.1 or later, which ships cryptsetup 2.8.1 and disables null ciphers in keyslots when the passphrase is non-empty. Contrast v1.13.0 additionally adds detached-header validation in guest memory and integrity protection for secure persistent storage.

4

What is the impact if exploitation succeeds?

The guest may open the attacker-supplied volume and write secrets in plaintext or encrypt them with a volume key known to the attacker. The malicious host can then read data that was expected to be confidential; persistent-volume integrity was not protected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203